vulnerability

WordPress Plugin: wp-reset: CVE-2021-36909: Improper Access Control

Severity
5
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:P)
Published
Nov 10, 2021
Added
May 15, 2025
Modified
Jul 10, 2025

Description

Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions less than or equal to 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.

Solution

wp-reset-plugin-cve-2021-36909
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.